Account Access Management & Permissions
From legacy architecture to Cloudflare One

From legacy architecture to Cloudflare One

3/13/2026 · Warnessa Weaver

What this post added

This post details a methodology for migrating legacy applications to Cloudflare One (SASE) in partnership with CDW. It introduces a phased rollout strategy that prioritizes coexistence over replacement, including application categorization (Tier 0-3) based on migration effort and technical complexity. Key technical contributions include the 'wrapping' of legacy applications using Cloudflare Access and Tunnel to modernize their security posture without code rewrites, enabling outbound-only connections with SSO and MFA, and applying edge policies for enhanced security. The post also outlines pre-migration audit steps focusing on architectural readiness, identity providers, dependency mapping, firebreak establishment, and persistent session stress testing, leveraging Cloudflare's Dynamic Path MTU Discovery (PMTUD) for persistent edge sessions.

Read the original post ↗